6.5
CVSSv2

CVE-2022-25311

Published: 08/03/2022 Updated: 10/10/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.3 | Impact Score: 5.9 | Exploitability Score: 1.3
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

A vulnerability has been identified in SINEC NMS (All versions >= V1.0.3 < V2.0), SINEC NMS (All versions < V1.0.3), SINEMA Server V14 (All versions). The affected software do not properly check privileges between users during the same web browser session, creating an unintended sphere of control. This could allow an authenticated low privileged user to achieve privilege escalation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

siemens sinec network management system

siemens sinema server 14.0

ICS Advisories

Siemens SINEC NMS
Critical Infrastructure Sectors: Energy